{
  "query": {
    "kev": "1",
    "page": "71"
  },
  "count": 20,
  "total": 1739,
  "page": 71,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T22:50:31.810Z",
    "kev": "2026-10-08T23:50:33.345Z",
    "epss": "2026-10-08T19:01:23.474Z",
    "breaches": "2026-10-08T18:49:28.295Z",
    "posts": "2026-10-08T23:50:33.664Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=71",
    "next": "https://spydr.io/threats.json?kev=1&page=72"
  },
  "coverage": {
    "cves_published_since": "2026-06-11",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2021-40870",
      "url": "https://spydr.io/cve/CVE-2021-40870",
      "published": "2021-09-13T08:15:13.913Z",
      "modified": "2026-06-17T04:07:34.377Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.93019,
      "epss_percentile": 0.99832,
      "exploited": true,
      "kev": {
        "added": "2022-01-18",
        "due": "2022-02-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "aviatrix"
      ],
      "products": [
        "aviatrix controller"
      ],
      "cwes": [
        "CWE-23"
      ],
      "description": "An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal."
    },
    {
      "id": "CVE-2021-32648",
      "url": "https://spydr.io/cve/CVE-2021-32648",
      "published": "2021-08-26T19:15:07.230Z",
      "modified": "2026-06-17T03:53:20.713Z",
      "score": 9.1,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.90418,
      "epss_percentile": 0.998,
      "exploited": true,
      "kev": {
        "added": "2022-01-18",
        "due": "2022-02-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "octobercms"
      ],
      "products": [
        "octobercms october"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. The issue has been patched in Build 472 and v1.1.5."
    },
    {
      "id": "CVE-2021-33766",
      "url": "https://spydr.io/cve/CVE-2021-33766",
      "published": "2021-07-14T18:15:10.380Z",
      "modified": "2026-08-10T19:58:44.540Z",
      "score": 7.3,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
      "score_source": "microsoft.com",
      "epss": 0.98176,
      "epss_percentile": 0.99914,
      "exploited": true,
      "kev": {
        "added": "2022-01-18",
        "due": "2022-02-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Exchange Server 2013 Cumulative Update 23",
        "Microsoft Exchange Server 2016 Cumulative Update 19",
        "Microsoft Exchange Server 2016 Cumulative Update 20",
        "Microsoft Exchange Server 2019 Cumulative Update 8",
        "Microsoft Exchange Server 2019 Cumulative Update 9"
      ],
      "cwes": [],
      "description": "Microsoft Exchange Server Information Disclosure Vulnerability"
    },
    {
      "id": "CVE-2021-22991",
      "url": "https://spydr.io/cve/CVE-2021-22991",
      "published": "2021-03-31T18:15:14.787Z",
      "modified": "2026-06-17T03:38:10.083Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.61064,
      "epss_percentile": 0.99139,
      "exploited": true,
      "kev": {
        "added": "2022-01-18",
        "due": "2022-02-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "f5"
      ],
      "products": [
        "BIG-IP"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual server may be incorrectly handled by the Traffic Management Microkernel (TMM) URI normalization, which may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may theoretically allow bypass of URL based access control or remote code execution (RCE). Note: Software versions which have reached End of Software Development (EoSD) are not evaluated."
    },
    {
      "id": "CVE-2021-21975",
      "url": "https://spydr.io/cve/CVE-2021-21975",
      "published": "2021-03-31T18:15:14.597Z",
      "modified": "2026-10-02T14:54:50.597Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.78001,
      "epss_percentile": 0.99566,
      "exploited": true,
      "kev": {
        "added": "2022-01-18",
        "due": "2022-02-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vmware"
      ],
      "products": [
        "VMware vRealize Operations"
      ],
      "cwes": [
        "CWE-918"
      ],
      "description": "Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials."
    },
    {
      "id": "CVE-2021-21315",
      "url": "https://spydr.io/cve/CVE-2021-21315",
      "published": "2021-02-16T17:15:13.050Z",
      "modified": "2026-06-17T03:35:16.700Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.90675,
      "epss_percentile": 0.99803,
      "exploited": true,
      "kev": {
        "added": "2022-01-18",
        "due": "2022-02-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "sebhildebrandt"
      ],
      "products": [
        "sebhildebrandt systeminformation"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "The System Information Library for Node.JS (npm package \"systeminformation\") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerability. Problem was fixed in version 5.3.1. As a workaround instead of upgrading, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() ... do only allow strings, reject any arrays. String sanitation works as expected."
    },
    {
      "id": "CVE-2021-25298",
      "url": "https://spydr.io/cve/CVE-2021-25298",
      "published": "2021-02-15T13:15:12.857Z",
      "modified": "2026-07-09T13:39:54.287Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.73641,
      "epss_percentile": 0.99462,
      "exploited": true,
      "kev": {
        "added": "2022-01-18",
        "due": "2022-02-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "nagios"
      ],
      "products": [
        "nagios xi"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server."
    },
    {
      "id": "CVE-2021-25297",
      "url": "https://spydr.io/cve/CVE-2021-25297",
      "published": "2021-02-15T13:15:12.793Z",
      "modified": "2026-07-09T13:39:51.737Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.56659,
      "epss_percentile": 0.99043,
      "exploited": true,
      "kev": {
        "added": "2022-01-18",
        "due": "2022-02-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "nagios"
      ],
      "products": [
        "nagios xi"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server."
    },
    {
      "id": "CVE-2021-25296",
      "url": "https://spydr.io/cve/CVE-2021-25296",
      "published": "2021-02-15T13:15:12.683Z",
      "modified": "2026-07-09T13:39:49.130Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.71935,
      "epss_percentile": 0.99416,
      "exploited": true,
      "kev": {
        "added": "2022-01-18",
        "due": "2022-02-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "nagios"
      ],
      "products": [
        "nagios xi"
      ],
      "cwes": [],
      "description": "Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server."
    },
    {
      "id": "CVE-2020-13671",
      "url": "https://spydr.io/cve/CVE-2020-13671",
      "published": "2020-11-20T16:15:15.433Z",
      "modified": "2026-06-17T02:53:32.867Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.3535,
      "epss_percentile": 0.98413,
      "exploited": true,
      "kev": {
        "added": "2022-01-18",
        "due": "2022-07-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Drupal"
      ],
      "products": [
        "Drupal Core"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74."
    },
    {
      "id": "CVE-2020-13927",
      "url": "https://spydr.io/cve/CVE-2020-13927",
      "published": "2020-11-10T16:15:11.807Z",
      "modified": "2026-06-17T02:53:54.840Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99778,
      "epss_percentile": 0.99954,
      "exploited": true,
      "kev": {
        "added": "2022-01-18",
        "due": "2022-07-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "apache"
      ],
      "products": [
        "Apache Airflow"
      ],
      "cwes": [
        "CWE-306",
        "CWE-1188",
        "CWE-1056"
      ],
      "description": "The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the default has been changed to deny all requests by default and is documented at https://airflow.apache.org/docs/1.10.11/security.html#api-authentication. Note this change fixes it for new installs but existing users need to change their config to default `[api]auth_backend = airflow.api.auth.backend.deny_all` as mentioned in the Updating Guide: https://github.com/apache/airflow/blob/1.10.11/UPDATING.md#experimental-api-will-deny-all-request-by-default"
    },
    {
      "id": "CVE-2020-14864",
      "url": "https://spydr.io/cve/CVE-2020-14864",
      "published": "2020-10-21T15:15:24.107Z",
      "modified": "2026-06-17T02:55:42.183Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "oracle.com",
      "epss": 0.97233,
      "epss_percentile": 0.99895,
      "exploited": true,
      "kev": {
        "added": "2022-01-18",
        "due": "2022-07-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation"
      ],
      "products": [
        "Oracle Corporation Business Intelligence Enterprise Edition"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)."
    },
    {
      "id": "CVE-2020-11978",
      "url": "https://spydr.io/cve/CVE-2020-11978",
      "published": "2020-07-17T00:15:10.337Z",
      "modified": "2026-06-17T02:51:10.520Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99189,
      "epss_percentile": 0.99934,
      "exploited": true,
      "kev": {
        "added": "2022-01-18",
        "due": "2022-07-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation"
      ],
      "products": [
        "Apache Software Foundation Apache Airflow"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow which would allow any authenticated user to run arbitrary commands as the user running airflow worker/scheduler (depending on the executor in use). If you already have examples disabled by setting load_examples=False in the config then you are not vulnerable."
    },
    {
      "id": "CVE-2021-27860",
      "url": "https://spydr.io/cve/CVE-2021-27860",
      "published": "2021-12-08T17:15:10.800Z",
      "modified": "2026-06-17T03:45:32.300Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.39824,
      "epss_percentile": 0.98592,
      "exploited": true,
      "kev": {
        "added": "2022-01-10",
        "due": "2022-01-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "FatPipe"
      ],
      "products": [
        "FatPipe WARP",
        "FatPipe IPVPN",
        "FatPipe MPVPN"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. The FatPipe advisory identifier for this vulnerability is FPSA006."
    },
    {
      "id": "CVE-2021-22017",
      "url": "https://spydr.io/cve/CVE-2021-22017",
      "published": "2021-09-23T13:15:08.207Z",
      "modified": "2026-06-17T03:36:33.670Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.49177,
      "epss_percentile": 0.98859,
      "exploited": true,
      "kev": {
        "added": "2022-01-10",
        "due": "2022-01-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vmware"
      ],
      "products": [
        "VMware vCenter Server, VMware Cloud Foundation"
      ],
      "cwes": [],
      "description": "Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being accessed."
    },
    {
      "id": "CVE-2021-36260",
      "url": "https://spydr.io/cve/CVE-2021-36260",
      "published": "2021-09-22T13:15:07.690Z",
      "modified": "2026-06-17T03:58:34.080Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99869,
      "epss_percentile": 0.99963,
      "exploited": true,
      "kev": {
        "added": "2022-01-10",
        "due": "2022-01-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "hikvision"
      ],
      "products": [
        "hikvision ds-2cd2026g2-iu/sl firmware",
        "hikvision ds-2cd2046g2-iu/sl firmware",
        "hikvision ds-2cd2066g2-i(u) firmware",
        "hikvision ds-2cd2066g2-iu/sl firmware",
        "hikvision ds-2cd2086g2-i(u) firmware",
        "hikvision ds-2cd2086g2-iu/sl firmware",
        "hikvision ds-2cd2166g2-i(su) firmware",
        "hikvision ds-2cd2186g2-i(su) firmware",
        "hikvision ds-2cd2326g2-isu/sl firmware",
        "hikvision ds-2cd2346g2-isu/sl firmware",
        "hikvision ds-2cd2366g2-i(u) firmware",
        "hikvision ds-2cd2366g2-isu/sl firmware",
        "hikvision ds-2cd2386g2-i(u) firmware",
        "hikvision ds-2cd2386g2-isu/sl firmware",
        "hikvision ds-2cd2426g2-i firmware",
        "hikvision ds-2cd2446g2-i firmware",
        "hikvision ds-2cd2526g2-i(s) firmware",
        "hikvision ds-2cd2546g2-i(s) firmware",
        "hikvision ds-2cd2566g2-i(s) firmware",
        "hikvision ds-2cd2586g2-i(s) firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands."
    },
    {
      "id": "CVE-2020-6572",
      "url": "https://spydr.io/cve/CVE-2020-6572",
      "published": "2021-01-14T21:15:13.693Z",
      "modified": "2026-06-17T03:23:37.420Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.10586,
      "epss_percentile": 0.95679,
      "exploited": true,
      "kev": {
        "added": "2022-01-10",
        "due": "2022-07-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute arbitrary code via a crafted HTML page."
    },
    {
      "id": "CVE-2019-1458",
      "url": "https://spydr.io/cve/CVE-2019-1458",
      "published": "2019-12-10T22:15:16.103Z",
      "modified": "2026-08-12T05:17:25.097Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.74438,
      "epss_percentile": 0.99484,
      "exploited": true,
      "kev": {
        "added": "2022-01-10",
        "due": "2022-07-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows",
        "Microsoft Windows Server"
      ],
      "cwes": [],
      "description": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'."
    },
    {
      "id": "CVE-2019-1579",
      "url": "https://spydr.io/cve/CVE-2019-1579",
      "published": "2019-07-19T22:15:11.557Z",
      "modified": "2026-10-02T04:18:01.077Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.46239,
      "epss_percentile": 0.98785,
      "exploited": true,
      "kev": {
        "added": "2022-01-10",
        "due": "2022-07-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "paloaltonetworks"
      ],
      "products": [
        "Palo Alto Networks GlobalProtect Portal/Gateway Interface"
      ],
      "cwes": [
        "CWE-134"
      ],
      "description": "Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code."
    },
    {
      "id": "CVE-2019-10149",
      "url": "https://spydr.io/cve/CVE-2019-10149",
      "published": "2019-06-05T14:29:11.293Z",
      "modified": "2026-06-17T02:10:21.590Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99961,
      "epss_percentile": 0.99975,
      "exploited": true,
      "kev": {
        "added": "2022-01-10",
        "due": "2022-07-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "exim"
      ],
      "products": [
        "exim"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
